Validate embeddings before indexing to prevent silent corruption
Description
Gitlab::Llm::Embeddings::CodeEmbeddings never checked that the AI Gateway returned an embedding for every document sent. A short response, or a blank embedding in the right position, wrote straight to the search index. No error, no log, no retry.
I tested this against live Vertex AI with several edge cases and could not reproduce it. Vertex either returns a full response or rejects the whole request.
Neither the AI Gateway nor its dependencies validate this at all (ai_gateway/models/v2/embedding_litellm.py#L198), and the self-hosted model path shares that same unguarded code. So there's a real possibility a self-hosted embedding server can hit this with nothing to catch it.
This adds a check right after a successful response: match the count, reject blanks, raise instead of writing bad data. The error goes through the existing retry chain. No measurable performance cost.
Related to #598882 (closed).